feature: remove change password for admin

This commit is contained in:
antv
2026-07-08 13:45:23 +07:00
parent 6056e33ef8
commit 7d9ba527a3
5 changed files with 32 additions and 7 deletions
+1 -1
View File
@@ -62,7 +62,7 @@ class AuthController extends Controller
\Illuminate\Support\Facades\RateLimiter::clear($throttleKey); \Illuminate\Support\Facades\RateLimiter::clear($throttleKey);
$user = $result['user']; $user = $result['user'];
if ($user->first_login == \App\Models\User::FIRST_LOGIN_TRUE) { if ($user->role != \App\Models\User::ROLE_ADMIN && $user->first_login == \App\Models\User::FIRST_LOGIN_TRUE) {
return redirect()->route('login')->with('dialog_first_login', true); return redirect()->route('login')->with('dialog_first_login', true);
} }
@@ -12,7 +12,7 @@ class ForceChangePasswordMiddleware
{ {
public function handle(Request $request, Closure $next): Response public function handle(Request $request, Closure $next): Response
{ {
if (Auth::check() && Auth::user()->first_login == User::FIRST_LOGIN_TRUE) { if (Auth::check() && Auth::user()->role != User::ROLE_ADMIN && Auth::user()->first_login == User::FIRST_LOGIN_TRUE) {
if (!$request->routeIs('user.change_password') && !$request->routeIs('user.update_password') && !$request->routeIs('logout')) { if (!$request->routeIs('user.change_password') && !$request->routeIs('user.update_password') && !$request->routeIs('logout')) {
return redirect()->route('user.change_password'); return redirect()->route('user.change_password');
} }
+1 -1
View File
@@ -92,7 +92,7 @@ class AdminService implements AdminServiceInterface
'status' => User::STATUS_ACTIVE, 'status' => User::STATUS_ACTIVE,
'card' => 0, 'card' => 0,
'flag_send' => User::FLAG_SEND_DISABLED, 'flag_send' => User::FLAG_SEND_DISABLED,
'first_login' => User::FIRST_LOGIN_TRUE, 'first_login' => $data['role'] == User::ROLE_ADMIN ? User::FIRST_LOGIN_FALSE : User::FIRST_LOGIN_TRUE,
]); ]);
} }
+4 -4
View File
@@ -37,14 +37,14 @@ class AuthService implements AuthServiceInterface
public function getRedirectRouteForUser(User $user): string public function getRedirectRouteForUser(User $user): string
{ {
if ($user->first_login == User::FIRST_LOGIN_TRUE) {
return route('user.change_password');
}
if ($user->role == User::ROLE_ADMIN) { if ($user->role == User::ROLE_ADMIN) {
return route('admin.dashboard'); return route('admin.dashboard');
} }
if ($user->first_login == User::FIRST_LOGIN_TRUE) {
return route('user.change_password');
}
return route('user.dashboard'); return route('user.dashboard');
} }
} }
+25
View File
@@ -197,6 +197,31 @@ class LoginNotificationTest extends TestCase
$this->assertTrue(\Illuminate\Support\Facades\Auth::check()); $this->assertTrue(\Illuminate\Support\Facades\Auth::check());
} }
public function test_admin_first_login_does_not_redirect_to_change_password(): void
{
$admin = User::create([
'msnv' => 5007,
'name' => 'First Login Admin',
'mail' => 'first_admin@example.com',
'pass' => md5('password123'),
'departments' => 1,
'role' => User::ROLE_ADMIN,
'status' => User::STATUS_ACTIVE,
'card' => 10,
'flag_send' => User::FLAG_SEND_ENABLED,
'first_login' => User::FIRST_LOGIN_TRUE,
]);
$response = $this->post('/login', [
'mail' => 'first_admin@example.com',
'password' => 'password123',
]);
$response->assertRedirect(route('admin.dashboard'));
$response->assertSessionMissing('dialog_first_login');
$this->assertTrue(\Illuminate\Support\Facades\Auth::check());
}
/** /**
* Test Case 6: Brute-force protection * Test Case 6: Brute-force protection
*/ */